Junglewise Threat Intelligence

CVE-2026-21280: Adobe Illustrator untrusted search path code execution

CVE-2026-21280 · Severity: high · CVSS 8.6 · Published 2026-01-13

Technologies: Adobe Illustrator. Vendors: Adobe.

Executive brief

Adobe Illustrator contains a flaw in how it searches for programs and resources on disk, allowing an attacker to substitute a malicious program that the application will execute with user privileges. An attacker must trick a user into opening a specially crafted file, but once the file is opened, arbitrary code runs without additional interaction. This could allow an attacker to install malware, steal data, or take control of a user's workstation.

Technical details

The vulnerability is an untrusted search path issue affecting Illustrator's resource loading mechanism. When Illustrator searches for critical resources or programs, it does not properly validate the search order or paths used, allowing an attacker to place a malicious binary in a location that is checked before the legitimate one. An attacker must craft a malicious file and trick a user into opening it; upon opening, Illustrator will execute the attacker's code with the privileges of the current user. Versions 29.8.3, 30.0 and earlier are affected. A fix is presumed available in later versions.

Affected products

  • Adobe Illustrator 29.8.3, 30.0 and earlier

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats